<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Are logs in encrypted form while sending to management server? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Are-logs-in-encrypted-form-while-sending-to-management-server/m-p/163936#M29288</link>
    <description>&lt;P&gt;Thanks for your reply is there any way we can show that logs was encrypted during forwarding logs management server, &amp;nbsp;because auditor ask they same questions to us and if is it mentioned in any document please share if you have any docs or articles related to this topic.&lt;/P&gt;</description>
    <pubDate>Fri, 02 Dec 2022 09:23:15 GMT</pubDate>
    <dc:creator>usmanshah526</dc:creator>
    <dc:date>2022-12-02T09:23:15Z</dc:date>
    <item>
      <title>Are logs in encrypted form while sending to management server?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Are-logs-in-encrypted-form-while-sending-to-management-server/m-p/163290#M29136</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;I have one query about logs if any one know the answer please reply the same.&lt;/P&gt;&lt;P&gt;query is between management servers and gateways logs sending in which format like plain text and encrypted form?&lt;/P&gt;&lt;P&gt;and if it’s sending logs in plain format is it possible to man in the middle attacker to read the logs while sending to management server?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 27 Nov 2022 18:35:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Are-logs-in-encrypted-form-while-sending-to-management-server/m-p/163290#M29136</guid>
      <dc:creator>usmanshah526</dc:creator>
      <dc:date>2022-11-27T18:35:58Z</dc:date>
    </item>
    <item>
      <title>Re: Are logs in encrypted form while sending to management server?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Are-logs-in-encrypted-form-while-sending-to-management-server/m-p/163339#M29150</link>
      <description>&lt;P&gt;Logs are sent through a protected channel with certificate-based authentication. I would be very surprised if you manage to do MitM attach on that.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2022 11:51:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Are-logs-in-encrypted-form-while-sending-to-management-server/m-p/163339#M29150</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-11-28T11:51:53Z</dc:date>
    </item>
    <item>
      <title>Re: Are logs in encrypted form while sending to management server?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Are-logs-in-encrypted-form-while-sending-to-management-server/m-p/163936#M29288</link>
      <description>&lt;P&gt;Thanks for your reply is there any way we can show that logs was encrypted during forwarding logs management server, &amp;nbsp;because auditor ask they same questions to us and if is it mentioned in any document please share if you have any docs or articles related to this topic.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 09:23:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Are-logs-in-encrypted-form-while-sending-to-management-server/m-p/163936#M29288</guid>
      <dc:creator>usmanshah526</dc:creator>
      <dc:date>2022-12-02T09:23:15Z</dc:date>
    </item>
    <item>
      <title>Re: Are logs in encrypted form while sending to management server?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Are-logs-in-encrypted-form-while-sending-to-management-server/m-p/163937#M29289</link>
      <description>&lt;P&gt;Its pretty simple - Capture the packet in your switch for port TCP/257 or even on mgmt server for port TCP/257. Try to read the logs. Since mgmt server is CA and then distributes certificates to difference component like firewalls and event viewer if deployed separately. The entire communication is encrypted using certificates&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 09:38:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Are-logs-in-encrypted-form-while-sending-to-management-server/m-p/163937#M29289</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2022-12-02T09:38:18Z</dc:date>
    </item>
    <item>
      <title>Re: Are logs in encrypted form while sending to management server?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Are-logs-in-encrypted-form-while-sending-to-management-server/m-p/163944#M29290</link>
      <description>&lt;P&gt;I dont believe there is specific document saying so, but its been that way with CP since the beginning.&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1551"&gt;@Blason_R&lt;/a&gt;&amp;nbsp; and&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;are 100% correct!&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 11:12:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Are-logs-in-encrypted-form-while-sending-to-management-server/m-p/163944#M29290</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-02T11:12:24Z</dc:date>
    </item>
    <item>
      <title>Re: Are logs in encrypted form while sending to management server?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Are-logs-in-encrypted-form-while-sending-to-management-server/m-p/163946#M29292</link>
      <description>&lt;P&gt;Also, to add to this, any communication between mgmt and gateway would be encrypted. Think of basic scenario...lets say SIC breaks on the firewall and you have to reset it. Key you put on for sic reset, does not matter, can be 12345678, its a one time password thats encrypted and its gone, thats it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But, if you really need document stating than, I will let someone else provide it, as I had never seen one stating so.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 11:44:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Are-logs-in-encrypted-form-while-sending-to-management-server/m-p/163946#M29292</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-02T11:44:52Z</dc:date>
    </item>
    <item>
      <title>Re: Are logs in encrypted form while sending to management server?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Are-logs-in-encrypted-form-while-sending-to-management-server/m-p/163952#M29296</link>
      <description>&lt;P&gt;Please refer to the section on SIC in the Security Management Admin Guide for your version, aswell as describing the encryption used by SIC it states this "trust" is required to send logs from Gateway to Management etc.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 11:58:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Are-logs-in-encrypted-form-while-sending-to-management-server/m-p/163952#M29296</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-12-02T11:58:38Z</dc:date>
    </item>
    <item>
      <title>Re: Are logs in encrypted form while sending to management server?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Are-logs-in-encrypted-form-while-sending-to-management-server/m-p/163953#M29297</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/85369"&gt;@usmanshah526&lt;/a&gt;&amp;nbsp; you can find these information in the documentation&amp;nbsp;&lt;A title="SIC" href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_SecurityManagement_AdminGuide/Topics-SECMG/Secure-Internal-Communication.htm?Highlight=SIC" target="_blank" rel="noopener"&gt;Secure Internal Communication (SIC)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;encryption type, which communication is encrypted etc.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 12:06:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Are-logs-in-encrypted-form-while-sending-to-management-server/m-p/163953#M29297</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2022-12-02T12:06:08Z</dc:date>
    </item>
  </channel>
</rss>

